Phishing Hack

TOTAL LOST $55.0M
High Phishing Attacks

What happened

On August 21, 2024, a victim lost $55.43 million in DAI after signing a phishing transaction that compromised their DeFi Saver Proxy, allowing the attacker to drain all the funds.

The exploit began when the victim, using the address 0xf2B88943…e13048, executed a setOwner transaction that inadvertently transferred ownership of their DeFi Saver Proxy contract to a phishing address 0x0000db5c…e70000. This phishing transaction resulted in the victim losing control of their proxy contract. Six hours later, when the victim attempted to execute a transaction, it failed because they were no longer the owner of the proxy.

Subsequently, the attacker changed the ownership of the proxy to 0x5D4b2A02…0459d4, allowing them to drain all the DAI from the compromised contract.

Exploit tx:

https://etherscan.io/tx/0xf70042bf…f45dc4

Case & protocol details

Classification Other
Protocol Type Exploit/Phishing

Evidence & learning

Sources and on-chain records

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.